2
Management
47
Statistics and High Availability
Statistics
are
not
correctly
mirrored
in
inactive
unit
of
an
HA
cluster.
This
topic
is
discussed
further
in
HA
issues
on
page
166
.
Events and logging
The
ability
to
log
and
analyze
system
activities
is
an
essential
feature
of
the
SEG.
Logging
enables
monitoring
of
the
SEG
status
and
health,
allows
auditing
of
network
usage,
and
assists
in
troubleshooting.
Log message generation
The
SEG
defines
a
large
number
of
different
log
event
messages
,
which
are
generated
as
a
result
of
associated
system
events.
Examples
of
such
events
are
the
establishment
and
ending
of
flows,
receipt
of
malformed
packets,
and
the
dropping
of
traffic
according
to
filtering
policies.
Log
events
are
always
generated
for
certain
aspects
of
the
SEG,
such
as
buffer
usage,
DHCP
clients,
high
availability,
and
IPsec.
The
generation
of
events
for
other
SEG
subsystems
such
as
DHCP
relay,
DHCP
servers,
and
IP
rules
can
be
enabled
as
needed.
Event types
The
SEG
defines
several
hundred
events
for
which
log
messages
can
be
generated.
The
events
range
from
high
‐
level,
customizable,
user
events
to
low
‐
level
and
mandatory
system
events.
For
example,
the
flow_open
event
is
a
typical
high
‐
level
event
that
generates
an
event
message
whenever
a
new
flow
is
established,
given
that
a
matching
security
policy
rule
exists
that
specifies
that
event
messages
should
be
generated
for
that
flow.
An
example
of
a
low
‐
level
event
would
be
the
startup_normal
event,
which
generates
a
mandatory
event
message
as
soon
as
the
system
starts
up.
Message format
All
event
messages
have
a
common
format
with
attributes
that
include
category,
severity,
and
recommended
actions.
These
attributes
enable
easy
filtering
of
messages,
either
within
the
SEG
prior
to
sending
to
an
event
receiver,
or
as
part
of
the
analysis
after
logging
and
storing
messages
on
an
external
log
server.
A
list
of
all
event
messages
can
be
found
in
the
SEG
‐
100
Log
Reference
.
That
guide
also
describes
the
design
of
event
messages,
the
meaning
of
severity
levels,
and
the
various
attributes
available.